CVE-2020-12888
Advisory lineage Upstream: 0 Downstream: 33
Modified
Published: 15 May 2020, 17:02
Last modified:04 Aug 2024, 12:11
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.11% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
15 May 2020, 17:02
Published
Vulnerability first disclosed
04 Aug 2024, 12:11
Last Modified
Vulnerability information updated
Description
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
- v2.0•MEDIUM•Score: 4.7AV:L/AC:M/Au:N/C:N/I:N/A:C
EPSS Trends
Current EPSS score: 0.11%• Percentile: 29%
Techniques & Countermeasures
- CWE-755•Improper Handling of Exceptional Conditions
The product does not handle or incorrectly handles an exceptional condition.
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 20.04
- debian•debian_linux
9.0
- fedoraproject•fedora
31 | 32
- linux•linux_kernel
≤ 5.6.13
- netapp•a700s_firmware
na
- netapp•active_iq_unified_manager
na
- netapp•bootstrap_os
na
- netapp•cloud_backup
na
- netapp•element_software
na
- netapp•h300e
na
- netapp•h300s_firmware
na
- netapp•h410c_firmware
na
- netapp•h410s_firmware
na
- netapp•h500e
na
- netapp•h500s_firmware
na
- netapp•h610c_firmware
na
- netapp•h610s_firmware
na
- netapp•h615c_firmware
na
- netapp•h700e
na
- netapp•h700s_firmware
na
- netapp•hci_management_node
na
- netapp•solidfire
na
- netapp•solidfire_baseboard_management_controller_firmware
na
- netapp•steelstore_cloud_integrated_storage
na
- opensuse•leap
15.1 | 15.2
References (13)
- https://lore.kernel.org/kvm/158871570274.15589.10563806532874116326.stgit%40gimli.home/
- https://lore.kernel.org/kvm/158871401328.15589.17598154478222071285.stgit%40gimli.home/
- http://www.openwall.com/lists/oss-security/2020/05/19/6
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXGMJHWTMQI34NJZ4BHL3ZVF264AWBF2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBEHRQQZTKJTPQFPY3JAO7MQ4JAFEQNW/
- https://security.netapp.com/advisory/ntap-20200608-0001/
- http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00009.html
- https://usn.ubuntu.com/4526-1/
- https://usn.ubuntu.com/4525-1/
- https://lists.debian.org/debian-lts-announce/2020/09/msg00025.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00032.html
- https://lists.debian.org/debian-lts-announce/2020/10/msg00034.html